Related Threat Clusters
-
China-Linked QTFY Group Targets Critical Infrastructure with Advanced Exploits
The Joint Cybersecurity Advisory JCSA-20260826-01, released on August 26, 2026, details ongoing activities by the China-linked hacking group QTFY, attributed to Nanjing Xinjiuwei Network Technology Co. Active since…
7 articles · Updated September 2, 2026 -
FamousSparrow APT Expands Targeting to Azerbaijani Energy Sector
FamousSparrow, a China-aligned APT group, launched a multi-wave cyberespionage campaign against an Azerbaijani oil and gas company from late December 2025 to February 2026. The attackers employed an evolved DLL…
10 articles · Updated May 13, 2026 -
Evolution of Chinese-Nexus Cyber Operations: Strategic Long-Term Threats
Recent research from Darktrace reveals the evolution of Chinese-nexus cyber operations over the past two decades, highlighting a shift from high-volume attacks to more strategic, identity-centric intrusions. This change…
381 articles · Updated April 2, 2026 -
StrikeShark Campaign Unleashes SharkLoader Malware to Deploy Cobalt Strike
A new malware family named SharkLoader has been discovered, linked to a campaign called StrikeShark, which targets various sectors, including a diplomatic organization in Indonesia. SharkLoader acts as a loader to…
14 articles · Updated June 25, 2026 -
Surge in Exploited CVEs and Malware Activity in H1 2026
In the first half of 2026, Insikt Group reported 215 actively exploited CVEs, marking a 34% increase from the previous year. Notably, AsyncRAT emerged as the leading malware, with nearly 60,000 unique hashes. The report…
2 articles · Updated September 4, 2026 -
Old Vulnerabilities Persist Amid AI Advancements
Organizations face heightened risks from old vulnerabilities as the AI era progresses. A recent study by TrendAI™ Research highlights that cybercriminals continue to exploit long-disclosed vulnerabilities, with the…
2 articles · Updated March 25, 2026 -
Mandiant Reports on UNC1549 Espionage Campaigns Targeting Aerospace and Defense
Mandiant has identified a surge in targeted campaigns by the threat group UNC1549, suspected to be linked to Iran, focusing on the aerospace, aviation, and defense sectors in the Middle East. Since mid-2024, these…
5 articles · Updated November 21, 2025 -
Bactor Ransomware Identified in Cybersecurity Monitoring
CYFIRMA Research and Advisory Team has identified Bactor Ransomware while monitoring underground forums. This ransomware targets Windows systems and affects multiple industries and technologies. The findings are part of…
5 articles · Updated November 20, 2025 -
Emergence of New Ransomware Variants: Bactor, ChickenKiller, and Midnight
Multiple ransomware strains, including Bactor, ChickenKiller, and Midnight, have been identified by CYFIRMA Research and Norton. Bactor and ChickenKiller ransomware target Windows systems, while Midnight ransomware has…
7 articles · Updated November 27, 2025
Recent Intelligence Reports
- H1 2026 Malware Vulnerability Trends — Recordedfuture · September 3, 2026
- Weekly Threat Bulletin – September 2nd, 2026 — F5 · September 2, 2026
- Qtfy Jcsa 20260826 01 Safebreach Coverage — www.safebreach.com · September 1, 2026
- StrikeShark Campaign Uses New SharkLoader Malware to Deploy Cobalt Strike Beacon — Gbhackers · June 25, 2026
- StrikeShark: investigating a new campaign delivering Cobalt Strike through SharkLoader — Securelist · June 24, 2026
- You Will Always Remember This As The Day You Finally Caught Famoussparrow — www.welivesecurity.com · May 13, 2026
- Chinese spy group caught lurking in Poland, Asia networks — Theregister · April 30, 2026
- What type of 'C2 on a sleep cycle' do they leave behind? Novel Chinese spy group found in critical networks in Poland, Asia — Theregister · April 30, 2026